Impact
The reported flaw is a heap‑based buffer overflow in Microsoft Office Excel that allows an unauthorized user to execute arbitrary code locally on the victim machine. This weakness stems from improper bounds checking when processing certain memory structures, enabling the overflow to corrupt control data. An attacker who can supply a crafted Excel file could achieve local code execution, which may lead to compromise of the affected application, escalation of privileges to the account under which the user is logged in, and potential access to data stored on that computer.
Affected Systems
The vulnerability affects a broad range of Microsoft Office products. As listed by the CNA, affected systems include Microsoft 365 Apps for Enterprise, Excel 2016, Office 2016, Office 2019, Office 365 for Mac, Office LTSC 2021, Office LTSC 2024, Office LTSC for Mac 2021, Office LTSC for Mac 2024, and the Office Online Server. Precise version numbers are not specified in the advisory, so any installation of these products that has not yet been updated may be vulnerable.
Risk and Exploitability
The CVSS score of 7.8 reflects a high potential impact if the vulnerability is exploited, and while the EPSS score is not available, the lack of a CISA KEV listing suggests that widespread exploitation is not yet observed. Nonetheless, the attack is local and requires the user to open a malicious Excel file. An attacker with the ability to supply such a file – for example, via phishing or supply chain compromise – could exploit the buffer overflow to run arbitrary code with the permissions of the logged‑in user. Administrators should therefore treat this flaw as a moderate to high risk.
OpenCVE Enrichment